C1 Identity & least privilege
Minimal 0.25 / 1.00
OpenHuman runs as the logged-in user with that user's file access, and in the shipped configuration nothing narrows that authority for file tools beyond a fixed block on credential stores such as ~/.ssh and ~/.aws. The shell tool strips the environment down to a short allowlist before running commands, but scheduled shell jobs and MCP server processes are started without that scrubbing. Connected apps reached through Composio are limited by a per-toolkit scope preference that allows reads and writes but not admin actions by default. A hijacked agent can therefore read most of the home directory, write files, reach the network and use connected accounts, with write actions on connected apps still needing a click in the chat.
C2 Approval gates
Minimal 0.35 / 1.00
OpenHuman ships a capable approval gate, but in the default configuration it only fires for a subset of tools that are hard-wired as consequential: Composio write actions, cron job changes, saving workflows and skill installs. The shell, file-write and HTTP tools ask the autonomy policy whether to prompt, and that policy is off by default, so they run without any approval. With the policy turned on (Supervised mode) every acting shell command, file write and network call is classified and parked for a human, with compound commands split and hidden execution blocked. Even then the approval card shows a code-built summary with recipients, message bodies and code fields masked, so the approver does not see the exact call.
C3 Tool & action scoping
Minimal 0.45 / 1.00
Tools are broad by default: a raw shell, file read and write anywhere outside a short list of credential and system directories, and HTTP fetching allowed to any public host. The opt-in autonomy policy adds real containment, resolving paths and checking them against the working folder, a command allowlist and per-tier blocking, but it is disabled in the shipped configuration. Outbound fetches are checked against an allowed-domains list whose default is every public site, with private addresses blocked by the network tools.
C4 Code-execution isolation
Minimal 0.38 / 1.00
The default user-facing agent runs shell, Python, Node and npm commands inside an OS jail (Landlock on Linux, Seatbelt on macOS) that confines writes to the working folder and strips the environment. Network access stays open for local sessions, the macOS profile allows reads everywhere, and on hosts with no usable jail (including Windows) commands silently run unconfined. Several paths sit outside the jail: scheduled shell jobs, MCP servers started as subprocesses, in-process file writes, and agents whose definition does not ask for a sandbox. An environment variable turns the jail off for the whole process.
C5 Untrusted input blast radius
Minimal 0.25 / 1.00
OpenHuman reads plenty of content its user did not write: web pages and search results, email and other connected-app data, synced memory sources and MCP tool results. Text entering the conversation passes a regex and heuristic prompt-injection screen, and remote MCP tool descriptions are screened before use. Nothing ties the agent's capabilities to having read untrusted content: in the shipped configuration a hijacked session can send data to any public host through the shell or HTTP tools and modify files without a human in the loop.
C6 Memory, context & configuration integrity
Minimal 0.30 / 1.00
When the user is signed in, memory is on by default: each turn is logged to the TinyHumans memory engine and relevant items are recalled into the next turn. Writes are scrubbed of secrets and personal data but not checked for instructions, so injected text can persist and resurface in later sessions. An AGENTS.md file in the working folder is loaded silently into the system prompt. Persona files such as SOUL.md are only protected from agent writes when the autonomy policy is enabled.
C7 Third-party extensions
Minimal 0.30 / 1.00
Third-party code mainly arrives as MCP servers the user declares in an mcp.json document; there is no install-from-catalog tool for MCP, and remote tool descriptions are screened before reaching the agent. Declared servers are launched as given, with no version pinning or hash check. Skills from the public catalog are Markdown instructions and their install tools require approval. MCP server processes run as the same user and, from the vendored client, start with the core's environment rather than a scrubbed one.
C8 Secrets & sensitive-data protection
Minimal 0.42 / 1.00
Secrets are handled well at rest: the OS keychain backs stored credentials, config secrets are encrypted, tool results are scrubbed of credential-looking strings before the model sees them, and the event journal masks process secrets. The weak point is telemetry: usage-data sharing is on by default and, with content capture also on by default, prompts, replies and truncated tool input and output are sent to the vendor's Langfuse proxy. Scheduled jobs and MCP servers also inherit the full process environment.
C9 Audit & traceability
Minimal 0.40 / 1.00
Agent runs are journaled as structured events with run ids, approvals and their outcomes are kept in a SQLite table, and shell commands are appended with fsync to an audit log. The journal is best-effort, sub-agent lineage is only partly threaded, and everything lives under the user's OpenHuman directory, where the in-process file tools can write when the autonomy policy is disabled.
C10 Limits & kill switch
Minimal 0.40 / 1.00
The default agent stops after 200 model iterations and most tools time out after 120 seconds, and delegation is capped at three levels. There is no cost or token cap in the default path: the cost middleware only observes. Shell and other scripting tools have no default timeout, the model chooses its own via timeout_secs, and an unsandboxed shell command that outlives its timeout is not killed.